Splunk Search

mulitvalue and single value difference

nehamvinchankar
Path Finder

How to get difference of  lastest value with now i have multiple values in latest column and only one value in now column i want output as difference 

latestnow
1701973800.000000
1701455400.000000
1701455400.000000
1700418600.000000
1700418600.000000
1702372339

 

1701973800.000000- 1702372339 =

1701455400.000000- 1702372339= 

like this 

Labels (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust
| mvexpand latest
| eval diff=now - latest

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust
| mvexpand latest
| eval diff=now - latest
Get Updates on the Splunk Community!

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...